- Q01Has Bubble ever supported SOX?
- No. Bubble has no public position on SOX, ICFR, or SOC 1. Bubble does hold SOC 2 Type II for the Security category, which is a different attestation — SOC 2 is about service-organisation security; SOC 1 is about controls over financial reporting. PCAOB and SEC reviewers treat them as non-interchangeable.
- Q02Doesn't Bubble's SOC 2 cover the SOX requirement?
- No, and this is the most common confusion. SOC 2 Type II under AT-C 205 attests to security (or availability, confidentiality, processing integrity, privacy). SOC 1 Type II under AT-C 320 attests to internal control over financial reporting at the service organisation. SOX 404 reviews ask for SOC 1 from any service organisation in ITGC scope. Bubble has no SOC 1.
- Q03What about plugins or workarounds?
- Irrelevant for SOX. Plugins don't bring SOC 1 evidence and can't substitute for it. They also complicate change management because plugin updates can change production behaviour without your review-and-approval workflow seeing them. For SOX-scoped environments, plugin governance is itself a control gap to remediate.
- Q04Can a hybrid setup work?
- Yes, this is the most common pre-IPO move. Carve financially-material flows — ledgers, revenue recognition, billing — onto AWS or Azure where the host's SOC 1 is available via Artifact or Trust Center. Keep Bubble for marketing, lead-capture, internal tools, and anything explicitly out of ICFR scope. Document the boundary and audit it every quarter.
- Q05How long does a SOX-ready rebuild take?
- Plan for 10–16 weeks of engineering for the carve-out itself: Next.js front end, Postgres on AWS RDS or Azure SQL with tamper-proof event log, role-based deployment, code review gates. The vendor SOC 1 Type II audit (if your customers are themselves SOX issuers) runs separately at $15k–$50k. Most teams parallel-run a SOC 2 readiness engagement to cover adjacent enterprise procurement.
- Q06Is SOC 1 separate from SOC 2?
- Yes. Different scope, different criteria, different report. SOC 1 tests controls over financial reporting at a service organisation under SSAE 18 AT-C 320. SOC 2 tests controls under the Trust Services Criteria under AT-C 205. Your customer's external auditor needs SOC 1 to rely on the service organisation for SOX 404; they may also ask for SOC 2 for general security assurance.
- Q07Does Bubble sign a DPA or BAA for SOX purposes?
- Bubble's GDPR-compliant DPA is largely irrelevant to SOX, which is about financial-reporting controls, not personal data. Bubble does not sign BAAs. For SOX what matters is the service-organisation control report (SOC 1) and the change-management evidence — neither of which Bubble provides at the level external auditors need for an in-scope ICFR environment.